ISC StormCast for Thursday, June 22nd, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 22 June 2023
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, June 22nd, 2003 edition of the Sands and the Storms and a storm |
| 0:07.4 | soundest Stormcast. My name is Johannes Ulrich and I'm recording from Stockholm, Germany. |
| 0:14.5 | We have observed in the past that a number of YouTube pages that at least at one point had a |
| 0:20.5 | significant number of subscribers |
| 0:22.4 | were all for a sudden taken over by crypto coin scams. Most recently, one of the probably |
| 0:30.8 | biggest creators on YouTube Linus Tech Tips was also the victim of a scam where a phishing email was used in order to |
| 0:41.2 | break in to their YouTube account and then replace it again with crypto coin scams. |
| 0:47.7 | So with all that, thanks to Kevin, a listener who forwarded us a sparefishing email that specifically targeted creators |
| 0:57.1 | like that. |
| 0:58.5 | In this particular example, the attacker is impersonating NordVPN. |
| 1:03.2 | You probably noticed a lot of YouTube creators are being sponsored by VPN providers, so |
| 1:10.2 | receiving an email from NordVPN, offering a sponsorship deal, may sound something plausible. |
| 1:17.6 | And they did a decent job in impersonating NordVPN. |
| 1:21.5 | They even went as far as registering a domain, NordVPN-media.com. And the recipient of the email is then enticed into |
| 1:31.0 | downloading a rar file that turns out, of course, to be Malver. And if the victim installs the |
| 1:38.1 | malware, well, apparently it's an info stealer, so that could then be used to, for example, |
| 1:45.0 | exfiltrate passwords or other credentials being used by the victim. |
| 1:50.2 | There is some evidence that suggests that the attacker here is Russian based on some Russian text snippets being used in email, |
| 1:59.7 | and also services like Mail.ru being used by |
| 2:04.5 | this particular attacker. And for more details, We Ching did a great job analyzing this particular |
| 2:13.2 | email and walking you through some of the different features, some of the obfuscations being used |
| 2:18.5 | and the exact chain that then in the end leads to installing the InfoSteeler. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

